Domains Contacted During Installation & Operation

During the installation and operation of MetaDefender Aether (previously known as MetaDefender Sandbox), the following domains will be contacted. Please note that this may change over time.

DomainsPurposeUsage TypeMetaDefender Aether Layer
api.metadefender.comMetaDefender Cloud Reputation APIOperation

Layer 1 - Threat Reputation

Layer 4 - Threat Hunting

opswat.com

update.dl.opswat.com

activation.dl.opswat.com

OPSWAT Activation Server and Update Infrastructure - Used for product activation and for downloading threat database updatesOperation

Layer 1 - Threat Reputation

Layer 2 - Dynamic Analysis

Layer 3 - Threat Scoring

my.opswat.comMyOPSWAT Portal used for OCM IntegrationOperationN/A

api.nuget.org

data.mcr.microsoft.com

mcr.microsoft.com

packages.microsoft.com

a-0016.a-msedge.net

Microsoft Container Registry and repository for .NET packages - Used by the Powershell emulatorInstallationN/A

archive.ubuntu.com

deb.debian.org

debian.map.fastlydns.net

security.ubuntu.com

Repositories of Ubuntu and Debian packages (can be any regional or local mirror) - Used directly for Ubuntu installations and used in Docker containers for both Ubuntu and RHEL installsInstallationN/A

auth.docker.io

docker.io

download.docker.com

registry-1.docker.io

production.cloudflare.docker.com

Used for Docker installation and downloading base images for Sandbox componentsInstallationN/A

bootstrap.pypa.io

files.pythonhosted.org

pypi.org

Python package repositories - Used when building the Docker image for the Sandbox webservice componentInstallationN/A

codecs.fedoraproject.org

mirrors.fedoraproject.org

Fedora’s geographically optimized mirror server that hosts Fedora packagesInstallationN/A

d2h67oheeuigaw.cloudfront.net

d2lzkl7pfhq30w.cloudfront.net

artifact.sandbox-prod.metadefender.com

Used for downloading phishpedia package from artifact.sandbox-prod.metadefender.com - Required for phishing detection ML modelInstallationN/A

dl-ssl.google.com

dl.google.com

Used for downloading Google Chrome - Required for URL rendering in the Sandbox transform Docker containerInstallationN/A
github.comUsed for getting YARA rules from OPSWAT fsYara repository: https://github.com/filescanio/fsYaraOperationLayer 2 - Dynamic Analysis

google.com

www.google.com

Used for basic connectivity checkInstallationN/A

ntp.ubuntu.com

time-a-g.nist.gov

time-a.nist.gov

NTP and time serversOperationN/A
pki.googGoogle Public Key InfrastructureInstallation OperationN/A
playwright.azureedge.netUsed for installing playwright in the Sandbox webservice docker imageInstallationN/A
rhui.us-west-2.aws.ce.redhat.comRHEL package repository (can be any regional or local mirror)InstallationN/A

For convenience, the same domains are also listed here:

Domains
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard